Skip to content

Legal

Privacy Policy

Last updated: July 18, 2026

This policy explains how Catavexa (“Catavexa,” “we,” “us,” or “our”) handles information when a merchant installs or uses the Catavexa Shopify application, connects Google Merchant Center, or visits this website.

1. Who operates Catavexa

Catavexa is operated by the Catavexa development and service team. Privacy questions and requests can be sent to privacy@catavexa.com. Support questions should be sent to support@catavexa.com.

2. Information we process

Shopify account and catalog data

  • Shop domain, shop information, installation state, scopes, and app configuration.
  • Products, variants, inventory, prices, currencies, images, product URLs, metafields, Markets, and translations.
  • Feed settings, mappings, rules, revisions, and synchronization preferences.
  • Shopify OAuth and session tokens needed to provide the service.

Google Merchant Center data

  • Merchant Center account IDs, account metadata, and selected data sources.
  • Product input records, processed product state, and product or account issues.
  • Google OAuth access and refresh tokens needed to maintain an authorized connection.

Operational data

  • Synchronization, webhook, audit, billing-state, error, security, and support records.
  • Basic website request data such as IP address, user agent, requested page, and request time when recorded by hosting or security logs.

Catavexa does not require customer personal data, order data, payment card data, customer addresses, or customer email addresses for its core product-feed function. Merchants should not submit that information through product text or support requests unless necessary.

3. Why we use information

  • Authenticate the Shopify store and maintain the app installation.
  • Import, transform, validate, and synchronize catalog data.
  • Connect to Google Merchant Center and manage authorized product data operations.
  • Retrieve processed product state and diagnose product or account issues.
  • Provide monitoring, reconciliation, alerts, history, revision, and rollback features.
  • Enforce plan limits and reflect Shopify-managed billing state.
  • Secure, troubleshoot, support, and improve the service.
  • Meet legal obligations and respond to valid privacy requests.

4. Google API data

When a merchant connects Google Merchant Center, Catavexa accesses Merchant Center account information, data sources, product records, product processing status, and product or account issues. Catavexa uses this information only to synchronize Shopify product data with Google Merchant Center, diagnose feed issues, and display synchronization status. Catavexa does not sell Google user data.

Catavexa’s use and transfer of information received from Google APIs will follow the Google API Services User Data Policy, including its Limited Use requirements, where applicable.

5. AI-assisted features

When a merchant requests an AI suggestion or explanation, relevant product text, structured catalog facts, and issue context may be sent to the configured AI service provider to generate the requested output. Catavexa does not intentionally send OAuth tokens, payment data, customer lists, or unrelated merchant data in AI prompts.

AI suggestions are reviewable and reversible. AI is not allowed to independently change critical commercial fields such as price, currency, availability, GTIN, SKU, inventory quantity, variant identity, or landing-page URL. Catavexa does not use merchant data to train Catavexa-owned general-purpose AI models. Provider handling is governed by the applicable service agreement and configuration.

6. Storage, security, and access

Catavexa uses HTTPS for data in transit, tenant-scoped access controls, secret management, sensitive-field log redaction, and encrypted token storage in production. Access to production data is limited to authorized personnel and service providers who need it to operate, secure, or support Catavexa.

No online service can guarantee absolute security. Security concerns can be reported to security@catavexa.com.

7. Service providers and disclosures

Catavexa may use infrastructure hosting, database, logging, monitoring, email, support, and AI service providers to operate the service. Shopify and Google also process data as the connected platforms selected by the merchant. An AI provider is used only when the relevant feature is configured and requested.

We may disclose information when required by law, to protect the service or its users, in connection with a business transaction, or with the merchant’s direction. Catavexa does not sell merchant personal information or catalog data.

8. Retention, uninstall, and deletion

When Catavexa is uninstalled, new synchronization and scheduled processing stop. Catavexa retains account, configuration, security, billing-state, and audit information only for as long as reasonably necessary for service recovery, legal compliance, dispute resolution, security, and enforcement, after which it is deleted or de-identified. Different record types may have different retention periods.

Merchants may request deletion at any time by emailing privacy@catavexa.comwith the .myshopify.com store domain. We may verify authority over the store before acting. Some records may be retained where legally required or necessary to document security and privacy compliance. Uninstalling Catavexa does not automatically delete data already held by Shopify or Google.

9. Merchant rights and choices

Depending on location, merchants or individuals may have rights to access, correct, delete, restrict, or object to certain processing, or receive a portable copy of personal information. A merchant can disconnect Google, uninstall Catavexa, decline AI suggestions, and contact us to exercise applicable rights.

10. Changes and contact

We may update this policy as Catavexa, its providers, or legal requirements change. The current version and updated date will be posted here. Contact privacy@catavexa.comfor privacy questions or requests.